[22762] in Kerberos

home help back first fref pref prev next nref lref last post

Re: validating keytab files: Cannot find KDC for requested realm

daemon@ATHENA.MIT.EDU (Frank Balluffi)
Tue Oct 26 21:30:41 2004

To: kerberos@mit.edu
Message-ID: <OF82100109.FA1791D9-ON85256F3A.0007E3F2@db.com>
From: "Frank Balluffi" <frank.balluffi@db.com>
Date: Tue, 26 Oct 2004 21:29:02 -0400
MIME-Version: 1.0
Content-type: text/plain; charset=us-ascii
Errors-To: kerberos-bounces@mit.edu


Adding "dns_lookup_kdc = true" to the [libdefaults] section of krb5.conf seems to fix the problem.

Frank



                                                                                                                                           
                      "Frank Balluffi"                                                                                                     
                      <frank.balluffi+exter        To:       kerberos@mit.edu                                                              
                      nal@db.com>                  cc:                                                                                     
                      Sent by:                     Subject:  validating keytab files: Cannot find KDC for requested realm                  
                      kerberos-bounces@mit.         whilegetting initial credentials                                                       
                      edu                                                                                                                  
                                                                                                                                           
                                                                                                                                           
                      10/26/2004 04:39 PM                                                                                                  
                                                                                                                                           
                                                                                                                                           




I am able to validate (test) keytab files for service1/host1.us.foo.com@FOO.COM and service2/host2.us.foo.com@FOO.COM using the command "kinit -5 -k -t keytab-file service-principal" from host1.us.foo.com, but when I try to validate a keytab file for service3/host3.au.foo.com@FOO.COM from host1.us.foo.com I get the following error:

kinit(v5): Cannot find KDC for requested realm while getting initial credentials

krb5.conf says:

[realms]
    FOO.COM = {
        kdc = ...foo.com:88
        ...
   }

[domain_realm]
    .foo.com = FOO.COM

Is this behavior expected? Do I need to be "on" a host in .au.foo.com to validate a keytab for service3/host3.au.foo.com@FOO.COM? Thanks.

Frank


--

This e-mail may contain confidential and/or privileged information. If you are not the intended recipient (or have received this e-mail in error) please notify the sender immediately and destroy this e-mail. Any unauthorized copying, disclosure or distribution of the material in this e-mail is strictly forbidden.


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos





--

This e-mail may contain confidential and/or privileged information. If you are not the intended recipient (or have received this e-mail in error) please notify the sender immediately and destroy this e-mail. Any unauthorized copying, disclosure or distribution of the material in this e-mail is strictly forbidden.


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post